@teambit/preview
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo lockstep publishing across many @teambit packages; benign pattern. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Bundled webpack UI artifact, not obfuscated malicious code. | ai | |
| provenance | no-provenance | AI (provenance): Stable across versions; provenance absence is a best-practice gap, not a security defect. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established package; missing description is cosmetic, not a malware signal. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/static/js/main.b1c18cda.cjs | AI (source-diff): Webpack-bundled UI preview asset from stated build tooling migration, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/static/js/main.b1c18cda.cjs | AI (source-diff): Bundled browser UI code (floating-ui etc.), no evidence of dropper behavior. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/static/js/main.b8138457.cjs | AI (source-diff): Bundled UI code naturally contains fetch + dynamic module exec patterns; no exfil destination found. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/static/js/main.b8138457.cjs | AI (source-diff): Webpack/rspack bundled UI preview artifact, not obfuscation; standard for this package's build output. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/static/js/main.72286528.cjs | AI (source-diff): Webpack-bundled UI preview artifact; minified, not obfuscated malware. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/static/js/main.72286528.cjs | AI (source-diff): Bundled dev-server/webpack client code, not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/static/js/main.58bd9271.cjs | AI (source-diff): Standard rspack/webpack UI bundle artifact; minified but not obfuscated, readable class names visible in sample. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/static/js/main.58bd9271.cjs | AI (source-diff): UI bundle legitimately contains fetch calls and dynamic requires; not dropper behavior. | ai | |
| dependencies | unvetted-dep:@teambit/react.webpack.react-webpack | AI (dependencies): First-party teambit package; consistent with the rest of the teambit dependency graph for this package. | ai | |
| source-diff | net-exec-file:artifacts/ui-bundle/static/js/main.02752e96.cjs | AI (source-diff): Network+exec pattern in a UI bundle is expected for a preview renderer; not dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/ui-bundle/static/js/main.02752e96.cjs | AI (source-diff): Standard rspack/webpack UI bundle artifact; minified but not obfuscated, readable class names visible in sample. | ai | |
| dependencies | unvetted-dep:@teambit/preview.cli.dev-server-events-listener | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/react | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.to-windows-compatible-path | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/rspack.modules.generate-asset-manifest | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/harmony | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/bit-error | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/component-id | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/legacy.constants | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/component.sources | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.path | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.crypto.sha1 | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/mdx.modules.mdx-v3-options | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/preview.ui.component-preview | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/harmony.modules.feature-toggle | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/preview.modules.preview-modules | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/preview.cli.webpack-events-listener | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/ui-foundation.ui.pages.static-error | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai | |
| dependencies | unvetted-dep:@teambit/harmony.modules.harmony-root-generator | AI (dependencies): Sibling package in the teambit/bit monorepo; stable ecosystem dependency. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 1.0.1070 | 56 / 11 | |
| 1.0.1064 | 56 / 11 | |
| 1.0.1055 | 56 / 11 | |
| 1.0.1054 | 56 / 11 | |
| 1.0.1052 | 56 / 11 | |
| 1.0.1051 | 56 / 11 | |
| 1.0.1029 | 56 / 11 | |
| 1.0.1021 | 56 / 11 | |
| 1.0.1018 | 56 / 11 | |
| 1.0.1008 | 56 / 11 | |
| 1.0.1000 | 56 / 11 | |
| 1.0.999 | 56 / 11 | |
| 1.0.992 | 56 / 11 | |
| 1.0.989 | 56 / 11 | |
| 1.0.988 | 56 / 11 | |
| 1.0.986 | 56 / 11 | |
| 1.0.972 | 56 / 11 | |
| 1.0.971 | 56 / 11 | |
| 1.0.970 | 56 / 11 | |
| 1.0.968 | 56 / 11 | |
| 1.0.927 | 56 / 11 | |
| 1.0.915 | 56 / 11 | |
| 1.0.810 | 52 / 12 | |
| 1.0.323 | 44 / 14 | |
| 1.0.318 | 43 / 14 | |
| 1.0.279 | 43 / 14 | |
| 1.0.262 | 43 / 14 | |
| 1.0.258 | 43 / 14 |
v1.0.1070
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1064
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1055
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1054
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1052
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1051
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.915
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.323
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.318
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.279
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.262
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.258
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.